back

by codazoda·6y ago·view on hn ↗
Seems like a lawsuit is the exact legal method that should be used to uncover the names that Facebook is seeking. As a Namecheap user who also sometimes uses whoisguard, I would expect Namecheap NOT to turn over any information until required to do so buy a subpoena signed by a judge. There is probably no other way to get one than to file a suit and ask a judge for it.
4 comments
I am fine with Facebook petitioning a court of competent jurisdiction and following legal due process to stop phishing activity. I am glad that Namecheap is not giving up this information without a proper court order. I am not happy with Facebook making this PR release trying to paint Namecheap in a bad light because they are standing up for privacy. This PR release is completely unnecessary if Facebooks intentions were simply to stop the phishing attacks.
While I'm happy that Namecheap won't reveal the names,I'm not happy that these kind of website names can not just be registered but also kept running for years.
Again, that's how it's supposed work though. If I pay for 10 years for my domain name, I don't want it to stop working because evilCorp makes a request to take it over (for whatever reason). If I am ruining the internet with a nefarious use of my domain, then it should be easy enough to prove to a valid court, and then there should be a legit way to take over control. It shouldn't be impossible, but it shouldn't be a cake walk either.
A court from what country?
Whichever country the registrar associated with that domain is currently in?
Indeed, it's a difficult question. But we should rather be asking, why isn't there better cooperation to catch cyber-criminals across borders?
Maybe because some governments are directly involved in the cyber crime?
Some? More like basically all.
What's a crime in my country is not necessarily a crime in yours. And international law without extradition backing it is at best a suggestion.
Absolutely, especially in terms of copyright and liability (of open computer systems, e.g. Germany's open WiFi nonsense).

But in some cases good enough proof of unauthorised compromise of computer systems can be collected, in those cases, why isn't there any cooperation? E.g. botnet makers.

What type of heuristic can capture "these kind of website names"? There are too many possibilities.

Some companies have registered misspellings and openly hostile domain names similar to their trademark, but it's hard to consider all permutations e.g. https://bankofamericasucks.com redirects to Coin Wallet.

Trademark law, as far as I understand, is to prevent customer confusion. Customers should be able to trust their intuition on who made a given product.

Misspellings should be covered. But hostile uses should not.

Please define "hostile uses" in a way that can be interpreted by law enforcement and the courts.

If I register "facebook-sucks.com" and put a disclaimer that facebook is a registered trademark of Facebook Inc etc etc then I'm not attempting to confuse customers of facebook (btw, do "users" of facebook = "customers" of facebook?).

Therefore there is no trademark infringement and no cause for me to cease and desist.

That's different to registering "faceb00k.com" and trying to pass my site off as being facebook. That's exactly what trademark rights are there to protect. It's not the registering of the domain that is the infringement, it's the attempt to pass off my site as being facebook's. In that case, a court can order me to take down my content, and if "me" is not identifiable, then they can order my hosting provider to do the same.

Facebook itself has numerous different domains registered and its not known that some of them are facebook's registrations.

What goes under “hostile uses”? Would people be confused if I made “facebook-sucks.com”? Because if you let something like this through, Facebook has an incentive to go after things like that…
I did a bit of research on this when I started killedbygoogle.com . It’s fine to use a trademark when it is being used for criticism, parody, or other creative work. It’s not okay to use for impersonation, fraud, or other commercial purposes that mislead consumers to believe an endorsement or association with the trademark’s owner.
Trademark law is to prevent "damage" to brands, not protect customers. If a system was in place to protect the customers, it would be the customers who were deceived that sue and receive compensation, not the company owning the trademark.
> This PR release is completely unnecessary if Facebooks intentions were simply to stop the phishing attacks.

That's not their goal at all (obviously).

This is at best tangentially related, but I once had a business model where I asked people to send me a friend request on Facebook. Rather than give them the FB URL directly, I registered [name]onfacebook.com and just had that on the card they received. All the domain did was redirect to my profile. No interstitial, the URL was replaced on redirect, literally just so I could say "[name] on facebook dot com" and have be easy to remember.

Less than a week later I received a nastygram from FB legal about protecting their copyright and that they expected me to shut the domain down immediately.

Judging by the comments here, they are doing good publicity for Namecheap.

I expect the people who post on HN to be representative of people who buy domain names. So while it may be bad publicity for the general public, it doesn't really matter if potential customers see it as a good thing.

Question: If what the domain name holders are doing is illegal (presumably phishing for secrets; which is probably against some sort of misdirection or scam laws) why is Facebook doing the suing? Why aren’t police departments or federal investigation units the once asking judges for subpoenas and going after the actual criminals?

It feels like an unessisary and possibly harmful step for a non-victim private company to suing another non-criminal private company so they can get these criminals to justice.

It sounds like the fraudulent domains are foremost a trademark infringement.

The fact that the domains are used for phishing or to perpetrate criminal acts is a secondary matter that adds gravitas to Facebook's public presentation of why they are suing Namecheap.

The infringing parties are those that register the domains using Whoisguard, and Namecheap is a non-party witness to the infringement.

So, serving Namecheap a subpoena, and then suing them for compliance after they neglect to respond to the subpoena is apparently a normal method for getting information from an uncooperative non-party witness in a civil legal proceeding.

Presumably, once they are successful in their lawsuit and have the names of the individuals responsible for the domain names, they will hand the evidence over to the police for investigation of criminal acts such as wire-fraud etc.

https://www.weil.com/~/media/files/pdfs/subpoenas-using-subp...

Quite typical that the crime being investigated is a petty trademark infringement, while there are real victims who’s privacy and dignity is violated by these scammers.

It indeed disgusts me that as a society of laws we go after violent criminals, not because they violate real victims, but because they infringe on a trademark of a multi-billion dollar company.

I'm no expert, but as I understand things the cops don't give a shit. Like if you witness someone speeding, or if someone steals your bicycle.

They'll take a report if you want, but there are only so many detectives. And these internet crimes need so many special skills and cross jurisdictional lines so easily...

We could establish a specialist police unit with the skills and funding levels needed to go after crimes against Facebook. Facebook might even be willing to help with funding and training, and doubtless big copyright holders would also be interested. Personally I don't think that would be a step in the right direction though.

But violent crime is down over the last 30-years, seems to be more cops employed and less petty crime laws being enforced. Doesn’t quite make sense but I often hear this excuse.
I think we need to start thinking about scammers as violent criminals. Victims of scammers do feel extremely violated after the fact. They loose not only valuables, but also their dignity and their sense of security. Scamming is indeed a violent crime that causes significant harm to the victim.

I also get the sense that there is still a lot of victim blaming when it comes to scamming. This also has to change. Victims of scams have not done anything wrong. The criminals that scam other people are of full blame for their crimes, and they need to be brought to justice for their violent behaviour.

Can't just change the definition of violent. Agree that the crime is much more serious than it looks on the surface. There's probably a perfect word. Predatory?
Violence is already really loosely defined (e.g. violence seems to be done up the social hierarchy; e.g. a state is not considered violent if they deport a refugee, while a protestor is considered violent if they block traffic). But even in this loose definition scammers fit perfectly as being violent criminals. They intentionally cause significant harm to their victims with their actions.

A lot of definitions put a physical qualifier, but that is not how the term is used by English speakers, e.g. bullying or psychological tormenting, is violent even though it is only verbal.

> vi·o·lence | ˈvī(ə)ləns | noun

> behavior involving physical force intended to hurt, damage, or kill someone or something.

In every definition, violence requires physical force. Nobody calls psychological abuse violence, they call it "gaslighting" or "bullying" or "emotional trauma".

Both local police and the FBI rarely care about fraud or scams. Most local fraud seems to be caught by individuals hiring private investigators that are former law enforcement. And even then, the punishment to the con-artist is often 1-2 years.

It’s even worse if you use a credit card, get skimmed, have money stolen from you then your credit card company tries to deny your claim. No where in this situation are there police going to the ATM to view the video surveillance of who stole your money.

Most law enforcement seems to rely on identity fraudsters being high on drugs in cheap hotels and being caught with hardware / stolen cards etc etc.

Are more cops employed? In the UK at least police numbers were cut drastically. One of the many hilarious pledges of the newly elected Tory government of the UK is that they'd hire lots of extra police to fix problems that some might argue were caused by the er... Tory government which had cut police numbers...
They are too busy going after victimless crimes.
It should be a lawsuit against the unnamed clients, rather than the hosting provider itself. Namecheap is a third party here imo, but there is plenty of precedent and process in using a lawsuit to compel third parties to provide information via subpoena.
I would agree, but I don't understand why Facebook would file a lawsuit against Namecheap. I would have thought they'd file a lawsuit against John Does (the owners of the domains) and obtain an order from the Judge to compel Namecheap to reveal the names of the John Does.

Then again I haven't seen the court filings so maybe that's exactly what they did and Namecheap is just mentioned as an additional defendant.

Either way, I would also expect Namecheap not to reveal anything unless they are compelled to by court order or another legal obligation.